Debian Patches

Status for wget/1.24.5-2

Patch Description Author Forwarded Bugs Origin Last update
CVE-2024-38428.patch Properly re-implement userinfo parsing (rfc2396)
* src/url.c (url_skip_credentials): Properly re-implement userinfo parsing (rfc2396)

The reason why the implementation is based on RFC 2396, an outdated standard,
is that the whole file is based on that RFC, and mixing standard here might be
dangerous.
=?UTF-8?q?Tim=20R=C3=BChsen?= <tim.ruehsen@gmx.de> no 2024-06-02
wget-doc-remove-usr-local-in-sample.wgetrc corrects the wgetrc path from /usr/local/etc/ to /etc/wgetrc in the sample wgetrc no
wget-doc-remove-usr-local-in-wget.texi corrects the wgetrc path from /usr/local/etc/ to /etc/wgetrc in the documentation no
wget-passive_ftp-default make passive-ftp the default no

All known versions for source package 'wget'

Links